PT-2026-57298 · Vmware+1 · Rabbitmq+1
CVE-2026-57213
·
Published
2026-07-10
·
Updated
2026-07-10
CVSS v4.0
5.7
Medium
| Vector | AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions prior to 3.13.14
RabbitMQ versions prior to 4.0.19
RabbitMQ versions prior to 4.1.10
RabbitMQ versions prior to 4.2.5
Description
The rabbitmq federation management plugin fails to perform HTML escaping when rendering the
consumer tag field on the Federation Status page. This allows a user with permissions to configure a federation upstream or policy to execute arbitrary JavaScript in the browser of any user viewing that page.Recommendations
Update to version 3.13.14 or later.
Update to version 4.0.19 or later.
Update to version 4.1.10 or later.
Update to version 4.2.5 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq
Rabbitmq Federation Management